Palo Alto Networks zero-day exploited since March to backdoor firewalls
ID: 6ff1d84b-a8bc-5d96-8f67-c874397cb437
STIX ID: report--6ff1d84b-a8bc-5d96-8f67-c874397cb437
Feed Name: Bleeping Computer
Threat Score
Suspected state-sponsored actors (tracked by Volexity as UTA0218) have been exploiting a PAN-OS GlobalProtect zero-day (CVE-2024-3400) since late March to install a Python backdoor called 'Upstyle', execute commands via log-parsing, deploy additional tools (reverse shells, GOST) and exfiltrate sensitive artifacts including Active Directory databases and browser credential stores; Palo Alto disclosed mitigations and scheduled patches after being notified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
